Sanctions screening is the comparison of a customer, its beneficial owners, its counterparties and the details of a transaction against lists of restrictive measures before money or goods move. The comparison covers names, dates of birth, passport numbers, IMO numbers of vessels, aircraft tail numbers, blockchain addresses, commodity codes and addresses. The output is a decision by the operator with a recorded rationale: release, reject, freeze or block. Each of the four outcomes carries its own legal consequences and its own reporting.
Screening remains a distinct discipline within the compliance stack of a licensed operator: it does not replace a source-of-funds review and does not answer tax questions. A bank may also turn a customer away under its internal risk policy; to the customer such a refusal looks like a sanctions measure, yet it is governed by contract law and is challenged differently.
Concept
A sanctions instrument prohibits making funds and economic resources available to listed persons and requires what they already own to be frozen. The prohibition by itself does not tell a bank how to learn that the payee of a transfer is a designated person, or a company that person owns through two intermediate layers. Screening is how the prohibition is carried out in practice: every party and every transaction runs through a filter, an analyst reviews the matches, and the decision is documented.
The Wolfsberg Group's Guidance on Sanctions Screening separates two disciplines. Customer screening (also called name screening) checks the parties an institution enters into relationships with — at onboarding and throughout the lifecycle. Transaction screening checks movements of value between parties and must fire at a point where the transaction can still be stopped. The two have different inputs, different cadences and different failure modes, and neither substitutes for the other.
The scope of screening depends on the type of operator.
| Operator type | What is screened |
|---|---|
| Bank | Customers and UBOs at onboarding, the full book at every list update, payment message fields, correspondent flows, trade finance, securities settlement |
| EMI or PSP | The same payment filter plus the agent network: an agent holds no licence of its own, and its customers remain the principal's customers along with the liability |
| CASP | Names, blockchain addresses and the data travelling with a transfer under the Travel Rule |
| Corporate payer | Counterparties, their ultimate beneficial owners, destination country, commodity codes, shipping route |
The central difficulty is that the lists name only part of those caught by the prohibition. A company owned 50% or more by a designated person is blocked in the United States and frozen in the EU automatically, although its name appears on no list. A name filter is therefore only the first half of the job; the second is unpacking ownership and control far enough to see any designated persons behind the customer.
| Parameter | Value |
|---|---|
| International standard | FATF Recommendations 6 and 7: freezing "without delay", ideally within hours |
| Core lists | UN, OFAC SDN and non-SDN, EU consolidated list, UK Sanctions List, UAE Local Terrorist List |
| Ownership test | US and EU: 50% or more, aggregated; UK: more than 50%, no simple aggregation |
| Report to OFAC | 10 business days for blocked property and for rejected transactions |
| Report in the UAE | Freeze within 24 hours, report within 5 business days |
| US record retention | At least 10 years |
| EU from 10 July 2027 | Sanctions checks on customers and UBOs become part of CDD under the AMLR |
Where the Duty Comes From
The international baseline is set by FATF Recommendations 6 and 7: targeted financial sanctions on terrorism and proliferation financing are implemented "without delay". The FATF Glossary defines the term as "ideally, within a matter of hours" of a designation by the UN Security Council. That is what drives the speed at which lists must be loaded: the window between publication and the filter firing is measured in hours.
National regimes build on the UN minimum in different ways. In the EU, the base instrument for individual Russia measures is Regulation (EU) 269/2014: the funds of listed persons are frozen, and no funds may be made available to them directly or indirectly. The rule addresses any person within EU jurisdiction, including corporate payers and professional intermediaries. In the United States, blocking flows from IEEPA executive orders and binds all US persons and any property within the United States.
The United Kingdom uses the same architecture — SAMLA 2018 plus regime regulations — with one distinction: for breaches after 15 June 2022 civil liability is strict and knowledge or suspicion need not be proved, as set out in OFSI's enforcement guidance as updated on 9 February 2026.
From 2027 the EU brings sanctions checks inside its supervised AML regime. Article 10 of Regulation (EU) 2024/1624 (AMLR) requires the business-wide risk assessment to cover the "risks of non-implementation and evasion of targeted financial sanctions", and Article 20(1)(d) makes part of CDD the verification of whether the customer and its beneficial owners are subject to targeted financial sanctions and whether such persons control a corporate customer or hold more than 50% of its proprietary rights. Sanctions control becomes a matter for the AML supervisor, and AMLA moves to direct supervision of selected obliged entities from 2028 — see the EU AML package.
Lists and Ownership Tests by Jurisdiction
Each regime maintains its own list, and the lists differ: a person can be on the SDN List and absent from the EU list, and the other way round. An operator working across currencies and jurisdictions loads all of them and determines for each customer which regimes apply.
United States: SDN, the Non-SDN Lists and the 50 Percent Rule
OFAC's main list is the SDN List: the property of listed persons is blocked in full, and US persons are barred from any dealings with them. Alongside it sit the non-SDN lists, whose restrictions are narrower and specified record by record. They are often mistaken for SDN entries — and the operator then either blocks what it only had to reject, or lets through what was prohibited.
| List | Who is on it | What is prohibited |
|---|---|---|
| SSI | Persons in sectors of the Russian economy | Specific activities under directives, chiefly new debt and equity |
| NS-MBS | Persons subject to a "menu" of measures | Measures listed in the individual record; no full blocking |
| CAPTA | Foreign financial institutions | Opening or maintaining correspondent or payable-through accounts in the US |
| FSE | Violators of sanctions against Iran and Syria | Dealings by US persons with them |
| NS-CMIC | Chinese military-industrial companies under E.O. 14032 | Purchase or sale of their publicly traded securities |
All of these are collected in the Consolidated Sanctions List, which does not include the SDN List itself (that is published separately), and the filter has to know which list a match came from: the outcome depends on it.
The 50 Percent Rule (revised guidance of 13 August 2014) extends blocking to any entity owned, directly or indirectly, 50% or more in the aggregate by one or more blocked persons. Two SDNs holding 25% each make the company blocked, although its name is on no list. Indirect ownership is traced down the chain: a stake held by a subsidiary that a blocked person owns 50% or more of is attributed to that person in full. Control without a 50% stake does not by itself trigger blocking — FAQ 398 says so expressly — but OFAC warns that such an entity may be designated in its own right, and dealings in which a blocked person acts on its behalf are prohibited.
The main change of the past year is the erosion of the arithmetic. OFAC's Guidance on Sham Transactions & Sanctions Evasion of 31 March 2026 starts from the observation that blocked persons often give up property only on paper, and defines a sham transaction as a transfer that conceals a blocked person's continuing interest. The advisory expressly supplements the 50 Percent Rule and lists seven red flags:
- commercially unreasonable terms;
- transfers to family members or close associates;
- an unclear purpose for the transfer;
- unduly complex structures involving higher-risk jurisdictions;
- continued involvement of the blocked person;
- a transfer close to the date of designation;
- evasive answers about the blocked person's role.
The practical effect: a stake below half no longer settles the question by itself if it was reduced shortly before designation and in favour of relatives.
European Union: the Consolidated List, Ownership and Control
The European Commission maintains the consolidated list of persons, groups and entities subject to EU financial sanctions in machine-readable form; legal force lies with the Council regulations in the Official Journal, and amendments take effect on publication. The Council's updated Best Practices of 3 July 2024 (ST 11623/2024) set the ownership threshold at "50% or more of the proprietary rights of an entity or … a majority interest in it" and confirmed aggregation: where one designated person holds 30% and another 25%, the company is in principle treated as owned by designated persons. The Commission's Sanctions Helpdesk takes the same position. The Best Practices spell out control through eight free-standing criteria:
- the right to appoint or remove a majority of the members of the administrative, management or supervisory body;
- having appointed a majority of board members solely through voting rights in the current and previous financial year;
- control of a majority of shareholders' or members' voting rights, alone or under an agreement with others;
- the right to exercise dominant influence under an agreement or the articles;
- the practical power to exercise dominant influence, including through front companies;
- the right to use all or part of the entity's assets;
- managing the business on a unified basis while publishing consolidated accounts;
- sharing jointly and severally, or guaranteeing, the entity's financial liabilities.
One criterion is enough, and the control test operates regardless of the stake: a structure with 24% ownership and a contractual right of dominant influence is caught just as a majority holding is. The Commission's FAQ on asset freezes, as revised in May 2026, added that voting rights attached to shares are frozen in full and cannot be exercised directly or indirectly, and that the presumption of control is rebuttable case by case. This is the key difference from the US: the European control test extends the freeze automatically; the American one does not.
United Kingdom: a Single UK Sanctions List and the "More Than 50%" Test
Since 28 January 2026 the UK Sanctions List has been the only source of UK designations: the OFSI Consolidated List of Asset Freeze Targets closed and is no longer updated. The list is maintained by the FCDO and published in XML, CSV and other formats; according to OFSI's general guidance, new UK and UN listings appear in it within one working day. Systems still pulling the old OFSI file have been screening against stale data since late January 2026.
The UK ownership test is narrower than the European and American ones: more than 50% of shares or voting rights, and OFSI does not simply aggregate the holdings of different designated persons unless the shares are subject to a joint arrangement or one party controls the rights of another.
The control test, however, is wider. After the Court of Appeal in Mints v PJSC National Bank Trust [2023] EWCA Civ 1132 observed obiter that, read literally, any Russian state entity could be treated as controlled by the President, the government issued a clarification on public officials, and on 16 February 2026 OFSI opened a call for evidence on "hypothetical control". The exercise closed on 20 April 2026 and no government response has been published; the same document says aggregation and a "50% or more" formula are being explored.
The UN, Hong Kong, Singapore, the UAE and Switzerland
The UN Security Council Consolidated List brings together everyone subject to Security Council measures — 736 individuals and 275 entities across 14 regimes as of 4 September 2026 (the DPRK, ISIL and Al-Qaida, the Taliban, Libya, Yemen and others). Inclusion on the common list does not mean every measure applies to a given person: that depends on the regime.
Jurisdictions that implement only UN sanctions give banks a different picture.
| Jurisdiction | Binding by law | Autonomous sanctions |
|---|---|---|
| Hong Kong | UN measures under the United Nations Sanctions Ordinance (Cap. 537): regulations made by the Chief Executive on instructions from the PRC Ministry of Foreign Affairs | None; per the HKMA circular of 8 August 2020, unilateral sanctions of foreign governments have no legal status in Hong Kong |
| Singapore | UN measures through MAS regulations under the Financial Services and Markets Act 2022; for other persons the UN Act 2001 and the Terrorism (Suppression of Financing) Act 2002 | Yes, targeted: financial measures against Russia since March 2022 (MAS Notice SNR-N01) |
| UAE | The UN list and the national Local Terrorist List under Cabinet Decision 74 of 2020; implementation coordinated by the Executive Office for Control & Non-Proliferation | Only the national terrorist list |
| Switzerland | Embargo Act and SECO ordinances | Yes, largely following EU packages |
The absence of a statute does not cancel market practice. In the same circular the HKMA requires banks to adopt policies based on a balanced assessment of legal, business and commercial risks, and the Hong Kong government stressed as early as 2019 that it has neither the responsibility nor the authority to enforce other countries' unilateral sanctions. Any Hong Kong or Singapore bank with a US dollar correspondent account screens against the SDN List all the same — the mechanism is set out in the next section. Switzerland implements EU packages with a lag: on 22 May 2026 SECO transposed part of the 20th-package listings, and on 19 August the Federal Council adopted the remaining measures, in force from 20 August.
The Main Regimes Side by Side
Six parameters drive how a filter behaves: what happens to the money, how ownership is counted, where jurisdiction ends and what a mistake costs.
| Parameter | United States (OFAC) | European Union |
|---|---|---|
| Base instrument | IEEPA and executive orders, 31 CFR | Regulation 269/2014 (persons), 833/2014 (sectors) |
| What happens to the money | Blocking: moved to a blocked account, return to sender prohibited | Frozen in place, the account survives |
| Ownership test | 50% or more, direct or indirect, aggregated; control alone does not block | 50% or more, aggregated, plus a separate eight-criterion control test |
| Extraterritorial reach | US persons, USD clearing, US-origin goods and software, secondary sanctions | No direct secondary sanctions; anti-circumvention clause and tool |
| Maximum civil penalty | The greater of USD 377,700 per violation or twice the transaction value | Set by member states; Directive 2024/1226 sets minimum maxima |
| Criminal liability | Up to 20 years under IEEPA for wilful violations | At least 5 years under Directive 2024/1226 from EUR 100,000 |
| Parameter | United Kingdom | Switzerland |
|---|---|---|
| Base instrument | SAMLA 2018 and regime regulations | Embargo Act, SECO ordinances |
| What happens to the money | Frozen in place, the account survives | Frozen, reported to SECO |
| Ownership test | More than 50% without simple aggregation, plus a control test; under review | Follows the EU logic |
| Extraterritorial reach | No secondary sanctions; applies on a UK nexus | Autonomous implementation without extraterritorial effect |
| Maximum civil penalty | The greater of GBP 1 million or 50% of the breach value | SECO administrative measures |
| Criminal liability | Up to 7 years' imprisonment | Provided for in the Embargo Act |
The two Asian booking centres complete the set on the same axes.
| Parameter | Singapore (MAS) | Hong Kong (HKMA, SFC) |
|---|---|---|
| Base instrument | Regulations under s.192 FSMA 2022 for financial institutions; UN Act 2001 for everyone else | United Nations Sanctions Ordinance (Cap. 537) and its regulations |
| Autonomous measures | Financial measures against designated Russian banks and entities | None; foreign unilateral sanctions have no legal status |
| What happens to the money | Immediate freeze; no transactions or services | Frozen under the relevant regulation |
| Ownership test | Assets owned or controlled, directly or indirectly, by a designated person | Set regulation by regulation |
| Reporting | Inform MAS of assets of designated persons | Suspicious transaction report to the JFIU |
| Maximum penalty | Fine up to S$1 million (FSM Regulations); individuals under the UN Act up to S$500,000 and/or 10 years | — |
The difference that matters in practice is the Russia row. Singapore is the only Asian centre in this set with its own financial measures against Russia, applied through MAS to every financial institution in the city, and its regulations reach assets owned or controlled by a designated person directly or indirectly, per MAS guidance on targeted financial sanctions. Hong Kong applies UN measures only and routes every freeze through a suspicious transaction report to the Joint Financial Intelligence Unit, per the Commerce and Economic Development Bureau. Neither centre imposes US or EU lists by law, and both screen against them in practice for the reason set out in the next section. The same logic across more jurisdictions, including the UAE and the Gulf, is mapped in the sanctions map.
Secondary Sanctions and Why Banks in Asia and the Middle East Close Accounts
A transaction routed through a US correspondent can create a direct US sanctions nexus even if the operator has no US customers. US persons must comply with applicable US sanctions; certain prohibitions also reach non-US persons. US-origin goods, software and technology require a separate export-control and sanctions-program analysis: origin alone is not a universal OFAC jurisdiction test. The choice of correspondent chain is therefore a sanctions decision.
Secondary sanctions work even without a nexus. E.O. 14114 of 22 December 2023 amended E.O. 14024 to allow penalties against foreign financial institutions that conducted or facilitated significant transactions for persons designated under E.O. 14024 that operate in the technology, defence, construction, aerospace or manufacturing sectors, or involving Russia's military-industrial base. The sanction is a prohibition on, or strict conditions for, US correspondent accounts, or full blocking of the bank itself. OFAC's updated guidance for foreign financial institutions of 12 June 2024 widened the military-industrial base to all persons blocked under E.O. 14024, whatever their sector. After Rosneft and Lukoil were designated on 22 October 2025, dealings with them entered the same zone.
On 15 January 2025, OFAC designated Kyrgyzstan's Keremet Bank after describing its coordination with Russia's Promsvyazbank to conduct cross-border transfers. The case illustrates exposure arising from particular Russia-related transactions, not a uniform rule for every bank in Hong Kong, Singapore, the UAE, Türkiye or Central Asia. For a bank outside the United States, distinguish a direct obligation under an applicable sanctions prohibition, OFAC's separate authority to sanction a foreign financial institution for specified activity involving Russia's military-industrial base (including transactions in non-dollar currencies), and the bank's or its correspondent's own risk policy. OFAC's 2024 advisory recommends risk-based controls and, when appropriate, attestations from high-risk customers that they do not operate in specified sectors, transfer specified items to Russia or otherwise transact involving Russia's military-industrial base, including persons blocked under Executive Order 14024. It does not prescribe a blanket refusal based on Russian citizenship or address. The de-risking mechanics are covered in the articles on account closure and correspondent banking.
What Is Screened and When
Configuring a system around party names alone is the classic cause of a miss. The objects of screening are far wider.
Customers, UBOs, Controlling Persons and Counterparties
At onboarding the institution screens the customer, its directors and signatories, the ultimate beneficial owners and, for trusts and foundations, the controlling persons: settlor, trustee, protector and beneficiaries. The structure is unpacked far enough to run the ownership and control test under each applicable regime and, after OFAC's sham-transactions advisory, to assess recent transfers of stakes. The customer's counterparties are screened as they appear in payments and, in trade finance, before the deal is executed.
Payment Message Fields
Wolfsberg treats as mandatory for screening the parties to a transfer, agents and intermediary institutions, and free-text fields such as the payment purpose in SWIFT field 70, where names of vessels, contracts and goods regularly surface. Since 22 November 2025 cross-border SWIFT payments have run on ISO 20022, and from November 2026 unstructured addresses are no longer permitted. This helps screening: address and country arrive as separate elements, and the geographic filter stops guessing from a free-text line.
| Party | MT103 | ISO 20022 (pacs.008) |
|---|---|---|
| Payer | Field 50 | Dbtr, UltmtDbtr |
| Payee | Field 59 | Cdtr, UltmtCdtr |
| Banks in the chain | Fields 52, 53, 54, 56, 57 | DbtrAgt, IntrmyAgt1–3, CdtrAgt |
| Free text | Fields 70, 72 | RmtInf, Purp, InstrForCdtrAgt |
The Ultimate Debtor and Ultimate Creditor elements matter most: under MT the real payer behind an agent or payment company was often invisible.
Vessels, Aircraft, Addresses and Blockchain
Vessels are identified by IMO numbers, which do not change when a ship is repainted or reflagged. The EU's 21st package of 23 July 2026 added 41 vessels to the 632 already listed, bringing the shadow-fleet list to 673, and extended restrictions to vessels providing support services. Aircraft are listed by registration and serial numbers.
Addresses are checked along two lines: a match with a designated person's address, and location in a territory under a regional prohibition. In the EU that means Crimea and the non-government-controlled areas of the Donetsk, Kherson, Luhansk and Zaporizhzhia oblasts (Regulation 2022/263); in the US, Crimea under E.O. 13685 and the so-called DNR and LNR under E.O. 14065. The city in an address field often matters more than the surname. The check is completed by the customer's country of actual presence, the country of app log-in and the IP address of the transaction.
Blockchain addresses sit in an SDN record as a separate identifier. The Garantex and Grinex case is instructive: the exchange, first designated on 5 April 2022, moved its customers and funds to Grinex after its domain was seized and more than USD 26 million frozen on 6 March 2025, and on 14 August 2025 OFAC designated both platforms; the release cites more than USD 100 million in illicit-linked Garantex transactions since 2019. For a CASP an address match is only the starting point: risk carries one or two hops from a designated cluster, and static list matching does not catch those hops.
Goods
The Common High Priority Items List (CHPL), maintained by the US, the EU, Japan and the UK, contains 50 items by six-digit HS code — from integrated circuits to machine tools. For a payment operator this means checking the invoice and commodity code alongside the counterparty's name; EU goods restrictions and dual-use controls are covered in goods under EU sanctions.
When to Screen
Wolfsberg expects screening when a relationship is established, then on trigger events and whenever customer data or lists change; transaction screening happens at a point where the transaction can still be stopped.
| Moment | What is screened | Mode |
|---|---|---|
| Onboarding | Customer, UBOs, controlling persons, signatories | Before the account opens |
| Every payment | Parties, banks, free text, country | Real time, before execution |
| List update | The whole customer book | Batch run, usually daily |
| Customer event | New UBO, director, address, nationality | When data change |
| New sanctions package | Executed transactions over the period | Lookback |
OFAC amends the SDN List on any business day without a schedule; the EU publishes amendments in the Official Journal with immediate effect. A customer clean yesterday may be designated today, which is why daily re-screening of the book is standard, while the lookback finds breaches that then become the subject of voluntary disclosure.
Matching Technique and the Analyst's Work
Screening is fuzzy string comparison, and its pathologies are predictable. Wolfsberg defines fuzzy matching as comparing strings that differ yet are close in spelling, pattern or sound. The MAS paper Strengthening AML/CFT Name Screening Practices (April 2022) calls reliance on exact matches alone a control deficiency and notes that spelling differences caused by translation cannot be a reason to close an alert.
Transliterating Cyrillic
The same surname reaches a bank in Latin script from a passport, a registry extract, a counterparty's payment and a sanctions list — each under different rules. The machine-readable zone of a passport follows the ICAO Doc 9303 table; the US and UK boards on geographic names maintain BGN/PCGN; the international standard ISO 9:1995 uses diacritics, and its differences from the UN and BGN/PCGN systems are set out in the UN Working Group on Romanization Systems report.
| System | "Щукин Юрий" | Set by |
|---|---|---|
| ICAO Doc 9303 | SHCHUKIN IURII | ICAO, machine-readable travel document standard |
| BGN/PCGN | Shchukin Yuriy | US and UK boards on geographic names |
| ISO 9:1995 | Ŝukin Ûrij | ISO, international transliteration standard |
Three correct spellings of one person differ pairwise in both surname and given name. The filter has to normalise them to a common key or keep a dictionary of variants; exact matching alone misses two out of three. Swapped given name and surname, a patronymic in the first-name field, feminine surname endings and dropped soft signs come on top.
Thresholds, Tuning and False Positives
The match threshold is a trade-off between misses and an avalanche of alerts. No regulator publishes consolidated false-positive statistics; the industry figure of "95–99% false" circulates without a primary source. A verifiable benchmark comes from an ECB paper on screening and instant payments: at most banks between 3% and 15% of payments go to alerts and manual review.
Tuning reduces noise legitimately: excluding noise words such as LLC and Bank from comparison, weighting rare and common names differently, and "good-guy" lists of confirmed false matches with mandatory review whenever the list record changes. Wolfsberg expects testing to confirm that the system generates the expected alerts and that suppression rules match the institution's risk appetite. In practice that means regular runs of test sets with known spelling variants (above-the-line and below-the-line testing) and independent model validation.
Alert Review and Documentation
OFAC FAQ 5 sets out six steps: determine which list the match is against; whether there is a sanctions nexus; assess the quality of the match by full name, former names, aliases, nationality, passport, tax and national ID numbers, place and date of birth and address; decide whether the match is valid; determine whether to block or reject; report to OFAC within 10 business days. OFSI's general guidance distinguishes a name match (the details align) from a target match (likely the same person).
Wolfsberg requires the system to present the analyst with all customer and list data and to record the rationale for the decision. A note reading "false positive" without saying which identifier diverged reads, on inspection, as no review at all. The second line is sample-based QA of closed alerts and escalation of ambiguous cases to the MLRO or the sanctions function.
How this fails in real life is shown by the GBP 160,000 penalty on Bank of Scotland: the system did not recognise a spelling variant of a designated person's name, and the payment went through. OFSI named the causes: the configuration did not cover spelling and transliteration variants, there were no fallback procedures for automation failure, and training materials were not updated. Voluntary disclosure within two weeks was a mitigating factor.
What Happens on a Match
A confirmed match triggers one of three legal outcomes, all of which practitioners loosely call "blocked".
US blocking. Property in which a blocked person has an interest is taken out of circulation: the money goes to a separate interest-bearing blocked account, and return to the sender is prohibited because the return would itself be a dealing in blocked property. Blocking lasts until a licence or delisting.
EU and UK asset freeze. Funds are frozen where they sit: the account remains the customer's, the contract continues, interest accrues, any disposal is excluded.
Rejection. The payment involves no listed person but touches a prohibited sector, product, service or territory. It is rejected and returned to the sender. An operator that "blocks just in case" what should have been rejected has disposed of someone else's money without legal basis.
Reporting by Jurisdiction
Deadlines and recipients of reports differ more than the prohibitions themselves.
| Jurisdiction | What and to whom | Deadline |
|---|---|---|
| United States | Blocked property report to OFAC via ORS (31 CFR 501.603) | 10 business days; annual report as of 30 June due by 30 September |
| United States | Rejected transaction report (31 CFR 501.604) | 10 business days |
| United Kingdom | Relevant firms report knowledge or reasonable suspicion and frozen assets to OFSI | As soon as practicable; annual frozen assets review by 30 November |
| European Union | National competent authority of the member state of residence or location (Art. 8 of Regulation 269/2014) | Immediately; for unfrozen funds and movements in the two weeks before listing, within two weeks |
| UAE | FFR for a confirmed and PNMR for a partial match via goAML (CBUAE) | Freeze within 24 hours, report within 5 business days |
| Singapore | MAS — information on assets of designated persons | Under MAS regulations |
| Hong Kong | Suspicious transaction report to the JFIU on any asset frozen or action taken | On freezing |
In the UK, relevant firms include FSMA permission holders, currency exchange and money transmission businesses, auditors, lawyers and accountants, estate agents, casinos, dealers in precious metals and stones, cryptoasset exchanges and custodian wallet providers, as well as art market participants, high value dealers, insolvency practitioners and letting agents. The "reasonable cause to suspect" standard is objective: the question is whether an honest and reasonable person in those circumstances should have formed the suspicion. In the UAE a partial match stays suspended until the regulator responds, and a freeze under Cabinet Decision 74 is applied without prior notice to the person. In the US, transaction records are kept for at least 10 years, and blocked-property records for the whole blocking period plus 10 years.
Licences
The prohibition is not always absolute. OFAC issues general licences that apply to anyone meeting their conditions, and specific licences on application through OFAC's licensing portal. OFSI issues general and specific licences on the grounds set by the regime regulations; in 2024–2025 it took 904 decisions on specific licences and issued 19 general licences. In the EU, authorisations (derogations) are granted by national competent authorities. Applying for a licence is a routine path and creates no presumption of breach.
Enforcement and Penalty Formulas
US figures show larger cases at a stable count.
| Year | OFAC actions | Total | Largest case |
|---|---|---|---|
| 2024 | 12 | USD 48,790,404 | SCG Plastics — USD 20,000,000 |
| 2025 | 14 | USD 265,746,819 | GVA Capital — USD 215,988,868 |
| 2026, to 23 September | 7 | USD 284,145,655 | Adani Enterprises, 18 May — USD 275,000,000 |
Crypto has its own line: Exodus Movement — USD 3,103,360, ShapeShift AG — USD 750,000. The penalty formula is set by Appendix A to 31 CFR Part 501: the IEEPA maximum is the greater of USD 377,700 per violation (after the inflation adjustment of 15 January 2025) or twice the transaction value.
For a non-egregious case with voluntary self-disclosure the base is half the transaction value, capped at USD 188,850; without disclosure it is the schedule amount, capped at USD 377,700; for an egregious case, half or the full statutory maximum. Disclosure is not voluntary if a third party has already reported the violation, if it is incomplete, or if it lacks senior management authorisation.
The UK recalibrated incentives in OFSI's enforcement guidance as updated on 9 February 2026.
| OFSI parameter | Value |
|---|---|
| Voluntary disclosure discount | Up to 30%, down from 50% |
| Settlement discount | 20% if the case closes within 30 business days with no challenge |
| Early Account Scheme | Up to 20% |
| Fixed penalties | GBP 5,000 and GBP 10,000 for information, reporting and licensing breaches |
| Maximum penalty | The greater of GBP 1 million or half the breach value |
| Announced doubling | GBP 2 million or the full breach value; requires legislation, not enacted as of September 2026 |
OFSI's 2024–25 annual review records 394 reports of suspected breaches, 329 of them under the Russia regime, and 214 closed cases; OFSI's 2026–29 strategy promises public KPIs from the autumn review.
The EU criminalised sanctions violations through Directive (EU) 2024/1226, with a transposition deadline of 20 May 2025. It sets minimum maxima: at least five years' imprisonment for making funds available to designated persons from EUR 100,000 and for military and dual-use goods regardless of value, at least one year for failure to report; for legal persons, 1% of worldwide turnover or EUR 8 million for reporting offences and 5% or EUR 40 million for the rest. Gross negligence regarding military and dual-use goods is also punishable. On 24 July 2025 the Commission opened infringement proceedings against 18 member states that had not completed transposition, including Germany, France, Italy, Spain, Ireland and Cyprus.
The Russia Regime and Over-Compliance
The latest is the EU's 21st package of 23 July 2026, implemented among others through Council Regulations 2026/1844, 2026/1846 and 2026/1848. Its main measures for screening:
- 218 listings — 48 individuals and 170 entities, the largest batch in four years;
- asset freezes on 94 banks and major financial institutions;
- a transaction ban on 33 more Russian credit and financial institutions, one Kyrgyz bank connected to SPFS and three third-country banks;
- a transaction ban on 14 crypto platforms in Georgia, Panama, the UAE, the Marshall Islands, Kyrgyzstan and Belarus;
- 51 new dual-use export control entries.
The package created a power to ban crypto services in respect of an entire third country whose providers are systematically used for circumvention; as of September 2026 no country has been designated on that basis. The oil price cap auto-adjustment mechanism is paused until 15 July 2027, a notification regime applies to sales of LNG tankers, and the transaction ban on a Georgian refinery takes effect six months after adoption.
The 20th package of 23 April 2026 banned transactions with Russian crypto providers and decentralised platforms, the rouble stablecoin RUBx and the digital rouble, brought the number of banks cut off from the EU market to 70 and used the anti-circumvention tool against a country — Kyrgyzstan — for the first time. The 19th package of 23 October 2025 banned transactions in the A7A5 stablecoin and dealings with the Mir and SBP payment systems.
For private individuals the key provision is Article 5b of Regulation 833/2014: EU credit institutions may not accept deposits above EUR 100,000 per institution from Russian nationals, residents and Russian-established entities, and the same categories are barred from crypto services as defined in MiCA, payment instrument issuance, acquiring, payment initiation and e-money issuance. Neither rule applies to nationals of EU, EEA or Swiss states or to holders of temporary or permanent residence permits there.
The Commission FAQ of 13 March 2026 adds two points that matter for product mapping: renewal and reissue of a card count as new issuance, and a company established outside Russia does not fall into these categories merely because Russians control it, unless it is used as a circumvention channel.
The gap between this text and practice is over-compliance: an institution that exits customers on nationality alone, or applies a restriction beyond its stated scope, is acting under its own risk policy: the same FAQ confirms that Article 5b(2) does not require accounts to be closed or existing contracts terminated. Such a decision cannot be challenged on sanctions grounds; it is tested against the contract and consumer law, and in the EU Article 15 of Directive 2014/92/EU bars credit institutions from discriminating by nationality or place of residence against consumers legally resident in the Union when they apply for or access a payment account. The regimes are mapped in the sanctions hub, jurisdiction choice is covered under booking centres, and the China angle in payments with China.
The Operator's Sanctions Programme
The minimum components are set by OFAC's Framework for OFAC Compliance Commitments: management commitment, risk assessment, internal controls, testing and audit, training. Penalty mitigation is calculated from whether these five elements exist and work, and OFSI, European supervisors and correspondent banks in the Wolfsberg CBDDQ look at the same things.
The sanctions risk assessment is a stand-alone document: customer segments by nationality and residence, currencies and the resulting nexus, the correspondent chain, products mapped against Article 5b, the agent network, geography. Threshold calibration is derived from it; the reverse order, where the risk assessment describes a system already tuned, reads to a regulator as no assessment. Thresholds, transliteration coverage, handling of list records without structured identifiers, alert-review SLAs, re-screening and lookback are documented and reproducible on request. A missing configuration log is a defect in its own right: in the Bank of Scotland case OFSI penalised an ineffective control, and the missed payment served as proof.
A decision on voluntary disclosure is taken at board level within days, because a report by a third party strips disclosure of its voluntary character. Training is assessed on content — OFSI cited outdated training materials as a separate factor. Sanctions liability is not rented out together with a licence; how these elements fit an operator's banking is covered in banking for MSBs.
The Customer's View: Where Alerts Come From and How to Clear Them
A customer with nothing to do with sanctions lists still lands in alerts regularly, for three reasons. Surname: a common Slavic, Arabic or Chinese surname, once transliterated, matches dozens of SDN records, and a filter with a sensible threshold has to show them. Nationality and residence: a passport or residence in a country under sectoral restrictions triggers checks regardless of name, as Article 5b does in the EU for Russian nationals and residents. Address: a town in Crimea or the Donetsk or Luhansk region, or simply a street name shared with a designated company. For a company, beneficial owners, directors and counterparties are added, and an alert can arise on any of them.
What Speeds Up Clearing a False Match
An analyst closes an alert when at least one reliable identifier in the customer's data diverges from the list record. The comparison runs on the fields OFAC lists in FAQ 5, and a customer's pack is best assembled around them in advance:
- a passport copy with the machine-readable zone — date and place of birth, number, nationality;
- a second document with the same Latin spelling, or a change-of-name record if spellings differ;
- proof of residential address no older than three months;
- for a company, a registry extract, an ownership chart down to the ultimate beneficial owners with percentages, and UBO documents;
- for a payment, the contract or invoice explaining the purpose and the goods.
Clearing a false match takes from hours to several business days, longer if the request travels through a chain of correspondents. Where false alerts on the same customer recur, it is reasonable to ask the bank to add the confirmed divergence to its good-guy list — an internal bank measure, and a legitimate question.
If Funds Are Frozen or a Payment Is Stuck
The sender's bank almost never holds the payment. In a dollar chain the decision is made by the US correspondent, for which the payer is not a customer; the sender's bank is itself waiting for an answer. The first substantive question is in which institution and under which regime the money sits. The operator must not disclose the content of its report to the regulator, so the productive request is a transaction status letter: it is needed to apply for a licence.
A freeze has no term and lasts until delisting or a licence. In the US a removal petition is filed under 31 CFR 501.807: OFAC checks completeness within 7–10 business days, usually sends a questionnaire within 90 days, and the overall timeline is not fixed and runs to years.
In the EU listings are reviewed periodically and challenged before the General Court; in the UK there is ministerial review followed by judicial oversight; in the UAE a grievance about the national list goes to the Executive Office, and a rejection can be appealed to court within 60 days. Removal is achievable: in the 20th package the EU lifted restrictions on 11 vessels and 5 third-country financial institutions after they gave compliance commitments. The OFAC procedure is covered in more detail in OFAC, and the link to source-of-funds review in AML/KYC for private clients.
Popular, but It Ends Badly
The same mistakes recur among operators and customers.
| Mistake | Why it fails |
|---|---|
| Treating a 49% stake as safe | The EU control test fires regardless of the stake, and since 31 March 2026 OFAC tests whether a transfer was real. A transfer to a relative near the designation date plus continued involvement in management decides the question against the structure |
| Splitting stakes among several designated persons | The US and the EU aggregate the stakes of different designated persons: 30% and 25% produce a blocked company. The UK does not aggregate only absent a joint arrangement |
| Screening the customer without UBOs and controlling persons | A company owned by a designated person is not on any list. From 2027 the AMLR expressly requires checks on beneficial owners and persons controlling the customer |
| Exact-match-only configuration | MAS calls it a control deficiency, and the Bank of Scotland penalty arose from an unrecognised spelling. Three transliteration standards give three spellings of one surname |
| Screening party names only | Lists carry IMO numbers, tail numbers and blockchain addresses; a vessel name arrives in the purpose field, CHPL codes in the invoice |
| Blocking instead of rejecting | Different reporting and different treatment of the money; an error either way is a breach |
| Relying on onboarding screening | Lists change on any business day; without daily re-screening a customer's designation goes unnoticed |
| Still screening against the OFSI Consolidated List | The list closed on 28 January 2026; the only source of UK designations is the UK Sanctions List |
Dates Already Set
| Date | Milestone |
|---|---|
| 22 November 2025 | SWIFT: cross-border payments moved to ISO 20022 |
| 28 January 2026 | OFSI Consolidated List closed; the UK Sanctions List is the single source |
| 9 February 2026 | New OFSI guidance: disclosure discount cut from 50% to 30% |
| 31 March 2026 | OFAC: Guidance on Sham Transactions supplements the 50 Percent Rule |
| 23 July 2026 | EU 21st package: 218 listings, 94 banks, power for country-wide crypto bans |
| November 2026 | SWIFT: unstructured addresses no longer permitted in ISO 20022 |
| 23 January 2027 | Transaction ban on a Georgian refinery takes effect |
| 10 July 2027 | AMLR applies: sanctions checks on customers and UBOs become part of CDD |
| 15 July 2027 | Pause of the oil price cap auto-adjustment ends |
Q/A
Why is a payment stuck if neither sender nor payee is on a list?
The filter compares strings fuzzily, and a match on a spelling or transliteration variant, or a vessel name in the purpose field, raises an alert; per the ECB, 3% to 15% of payments go to alerts. The second reason is a sector, product or territory: the payment is rejected and returned. The third is the chain: in a dollar payment the decision is made by a US correspondent for which neither the sender nor its bank is a customer.
Which documents help clear a false match?
Those that show a divergence on a reliable identifier: a passport with date and place of birth and number, proof of address and, for a company, a registry extract and an ownership chart down to the UBOs with percentages. OFAC FAQ 5 lists exactly these fields: full name, aliases, nationality, passport, tax ID, place and date of birth, address. Review usually takes from hours to several business days.
What is the practical difference between US blocking and an EU freeze?
In the US the property moves to a separate blocked account and cannot be returned to the sender, because a return would itself be a dealing in blocked property. In the EU and the UK funds are frozen where they are: the account remains the customer's, the contract continues, disposal is excluded. A European freeze is lifted by licence or delisting without moving funds; a US block needs authorisation for any movement.
Does a stake below 50% guarantee that a counterparty is outside the restrictions?
No. The EU aggregates the stakes of several designated persons and applies eight free-standing control criteria, any one of which suffices. The US also aggregates, and although control without 50% does not block automatically, since 31 March 2026 OFAC tests whether a transfer of a stake was a sham. The UK requires more than 50% and does not aggregate absent a joint arrangement, but its control test is the widest and is under review.
Must a bank in Hong Kong or Dubai apply US and EU sanctions?
A bank outside the US or EU can still have direct obligations where the transaction falls within the relevant jurisdictional perimeter or a specific prohibition applies. Domestic sanctions rules alone do not answer that question. Separately, specified activities may create secondary-sanctions exposure under amended E.O. 14024 even in a non-dollar currency, and banks may apply stricter internal or correspondent-bank policies. A refusal or request for attestations therefore needs to be assessed against the actual transaction, parties and applicable rules.
Should an operator self-disclose a breach?
In the US voluntary self-disclosure of a non-egregious case cuts the base to half the transaction value, capped at USD 188,850 instead of USD 377,700. In the UK since 9 February 2026 the discount is up to 30%, combinable with 20% for settlement and up to 20% under the Early Account Scheme. Disclosure loses its voluntary character if a third party has already reported the breach, so the decision is taken within days.
How long does delisting take?
In the US OFAC checks a petition for completeness within 7–10 business days and usually sends a questionnaire within 90 days; the overall process runs to years. In the EU the decision is challenged before the General Court, in the UK through ministerial review and judicial oversight, in the UAE through a grievance to the Executive Office and a court appeal within 60 days of rejection. In the 20th package the EU lifted restrictions on 11 vessels and 5 financial institutions after compliance commitments.
How do Singapore and Hong Kong differ on sanctions?
Singapore implements UN measures and, since March 2022, its own financial measures against designated Russian banks and entities; its regulations cover assets owned or controlled by a designated person directly or indirectly, and a financial institution in breach faces a fine of up to S$1 million. Hong Kong implements UN measures only, under Cap. 537, reports freezes through suspicious transaction reports to the JFIU, and gives foreign unilateral sanctions no legal status. Banks in both centres still screen against US lists to protect their dollar correspondent accounts.